MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b1f10393b40f4b51855e4d63c5a1a212beb056b3c37528b7f30c80e5af9e6fe7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



AgentTesla


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: b1f10393b40f4b51855e4d63c5a1a212beb056b3c37528b7f30c80e5af9e6fe7
SHA3-384 hash: fb5fe1bad68b2bf7b828a1d3e8438777b4ead7dd229dc3ed08c0f84e25c7ca098c34fd873fa68893c1821ca6c1119c39
SHA1 hash: 9a929430a7d891c3b450d568969005ccdcc91772
MD5 hash: f21385c587e4fb690f8bbd44135911ed
humanhash: kilo-carolina-seven-cat
File name:DHL DELIVERY-AWB.rar
Download: download sample
Signature AgentTesla
File size:383'380 bytes
First seen:2020-05-31 22:08:48 UTC
Last seen:Never
File type: rar
MIME type:application/x-rar
ssdeep 6144:RpwK5eUiTO4nItjw2d/TVUkqDtRgAvRtGIAUl8zOTxEjdt0b5MBQuZg298bzB1U:Rr8VO4nIJbeHDtRgS4UrTbb548bl1U
TLSH DF84238FBB537F387363213A1BF21233636A371945426728531716A2988FF76BAB141D
Reporter abuse_ch
Tags:AgentTesla DHL rar


Avatar
abuse_ch
Malspam distributing AgentTesla:

HELO: indiacon.com
Sending IP: 193.56.28.232
From: DHL Express <support@indiacon.com>
Subject: DHL Delivery-AWB 31/05/2020 walter_bergen@deadlymob.org
Attachment: DHL DELIVERY-AWB.rar (contains "DHL DELIVERY-AWB.exe")

AgentTesla SMTP exfil server:
mail.zeusinfratech.com:587

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
n/a
Vendor Threat Intelligence
Gathering data
Threat name:
ByteCode-MSIL.Trojan.Kryptik
Status:
Malicious
First seen:
2020-05-31 10:37:26 UTC
AV detection:
17 of 48 (35.42%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

AgentTesla

rar b1f10393b40f4b51855e4d63c5a1a212beb056b3c37528b7f30c80e5af9e6fe7

(this sample)

  
Dropping
AgentTesla
  
Delivery method
Distributed via e-mail attachment

Comments